Skip to content
SND IT Solutions

Privacy Policy

Your privacy matters to us

How we collect, use, protect and keep your personal data, in line with the Data Privacy Act of 2012. Effective September 29, 2026.

SND IT Solutions ("we", "us", "our") respects your privacy and is committed to protecting your personal data in accordance with Republic Act No. 10173, the Data Privacy Act of 2012, its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC). This Privacy Policy explains what personal data we collect through our website snditsolution.com, why we collect it, how we protect it, how long we keep it, and the rights you have over it.

1. Who we are

SND IT Solutions is the personal information controller of the personal data described in this policy. You can reach us at:

2. Personal data we collect

a. Information you give us

When you use our contact form, we collect your name, email address, phone number (optional), the service you are interested in (optional) and the message you write. We also record the date and time you agreed to this Privacy Policy.

We do not ask for sensitive personal information (such as your race, health, religion, government-issued identification numbers or financial account details). Please do not include such information in your message.

b. Information collected automatically

Like most websites, when you visit our pages we automatically record technical information about the visit: your IP address, the country your connection comes from (as provided by our network security provider), your browser and device type, the pages you open, the date and time of each visit, and the website that referred you. We do not use this information to identify you personally.

c. Staff accounts

If you are a member of our team with access to the website's administration area, we keep your name, email address and a securely scrambled (hashed) version of your password, and a record of your activity in the administration area.

3. Why we use your personal data, and our legal basis

PurposeLegal basis under the Data Privacy Act
To reply to your inquiry, prepare a quotation, and communicate with you about the services you asked aboutYour consent, given when you submit the contact form (Section 12(a)), and steps you asked us to take before entering into a contract (Section 12(b))
To keep the website secure — detecting and blocking hacking attempts, spam and abuse — and to understand how many people visit which pagesOur legitimate interest in protecting our website, our visitors and our clients (Section 12(f)), which does not override your fundamental rights and freedoms
To comply with legal obligations and lawful orders of courts or government authoritiesCompliance with a legal obligation (Section 12(c))

We will not use your personal data for purposes that are not compatible with the ones above without informing you and, where required, asking for your consent. We do not send marketing messages unless you ask us to.

4. Automated security checks

Our website automatically reviews visits for signs of attacks — for example, attempts to open hacking-tool addresses, to inject harmful code, or to guess passwords. Each internet address is given a risk rating, and addresses that show clearly malicious behaviour may be blocked from the website by our administrator. No other decisions that affect you are made automatically. If you believe you were blocked by mistake, please contact us using the details in Section 13 and we will review it.

5. Cookies

We use only strictly necessary cookies: a session cookie that keeps the website working as you move between pages, and a security cookie that protects our forms against forgery. These cookies do not track you across other websites and are deleted when they expire or when you close your browser. We do not use advertising or tracking cookies. If we add analytics tools in the future, we will update this policy first.

6. Who we share your personal data with

We do not sell, rent or trade your personal data. We share it only with trusted service providers who process it on our behalf and under our instructions, as personal information processors:

  • Hostinger — hosts the server where our website and its database run;
  • Cloudflare — delivers our website securely and protects it against attacks;
  • Google (Gmail) — delivers the email notifications of your inquiries to our team.

Some of these providers may process data on servers located outside the Philippines. We remain responsible for your personal data wherever it is processed, and we use providers that apply security measures comparable to those required by Philippine law (Section 21 of the Data Privacy Act).

We may also disclose personal data when required by law, by a court order, or by a lawful request of a government authority.

7. How long we keep your personal data

  • Contact-form messages: two (2) years from the date we receive them, then automatically deleted — unless you become a client, in which case records related to our engagement are kept for as long as the engagement lasts and as required by tax and accounting laws.
  • Visit records (the pages opened, with IP address and browser information): ninety (90) days, then automatically deleted.
  • Security summaries of internet addresses: twelve (12) months after the last visit. Addresses we have blocked for malicious activity are kept for as long as the block is in place.
  • Staff accounts: for as long as the account is active.

When personal data is no longer needed, we delete it securely.

8. How we protect your personal data

We apply organizational, physical and technical security measures (Section 20 of the Data Privacy Act), including:

  • encrypted connections (HTTPS) for every page of our website;
  • access to personal data limited to authorized staff, with separate roles and permissions;
  • passwords stored only in a securely scrambled (hashed) form;
  • protection against automated attacks, continuous security monitoring and blocking of malicious visitors;
  • regular backups and prompt software updates;
  • confidentiality obligations for everyone who handles personal data on our behalf.

9. If a data breach happens

If a personal data breach occurs that is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and the affected individuals within seventy-two (72) hours of becoming aware of it, as required by NPC Circular No. 16-03 on Personal Data Breach Management, and we will take immediate steps to contain it.

10. Your rights as a data subject

Under the Data Privacy Act (Sections 16 to 18), you have the right:

  • to be informed whether and how your personal data is being processed;
  • to access your personal data that we hold;
  • to object to the processing of your personal data, and to withdraw your consent at any time;
  • to correct (rectify) personal data that is inaccurate or incomplete;
  • to erasure or blocking of personal data that is no longer necessary, was unlawfully obtained, or is being processed without your consent;
  • to data portability — to obtain a copy of your data in an electronic format you can use;
  • to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of personal data; and
  • to file a complaint with the National Privacy Commission.

Your lawful heirs and assigns may exercise these rights on your behalf when you are deceased or incapacitated (Section 17).

Withdrawing your consent does not affect processing we carried out before you withdrew it, and it does not affect data we must keep to comply with the law.

11. How to exercise your rights

Send your request to our Data Protection Officer using the details in Section 13. To protect your data, we may ask you to confirm your identity before acting on the request. We will respond within a reasonable time — generally within fifteen (15) working days — and we do not charge a fee for reasonable requests.

12. Complaints and the National Privacy Commission

If you have a concern about how we handle your personal data, please contact us first so we can resolve it quickly. You also have the right to lodge a complaint with the National Privacy Commission:

13. Contact our Data Protection Officer

For questions about this policy or to exercise your rights, contact:

Data Protection Officer
SND IT Solutions
Purok 3, San Teodoro, Bunawan, Agusan del Sur
Email: developer@snditsolution.com
Phone: 0963 750 9061

14. Children

Our website and services are intended for businesses and adults. We do not knowingly collect personal data from anyone under eighteen (18) years of age. If you are under 18, please ask a parent or guardian to contact us on your behalf.

15. Links to other websites

Our website links to other websites, such as the live systems in our portfolio. Those websites have their own privacy policies, and we are not responsible for how they handle personal data.

16. Changes to this policy

We may update this Privacy Policy when our practices or the law change. The effective date below shows when it was last updated. For significant changes, we will post a notice on our website.

Effective date: September 29, 2026